hardMultiple ChoiceObjective-mapped
CISSP Practice Question: A company's risk assessment identifies a high…
A company's risk assessment identifies a high likelihood of a data breach due to outdated encryption standards. The cost to upgrade encryption is $50,000, and the estimated loss from a breach is $2,000,000. The risk manager decides to implement the upgrade. Which risk treatment option is being applied?
⚠ Common exam trap
It's easy for candidates to confuse risk mitigation with risk avoidance, as candidates may think avoiding outdated encryption means avoiding the risk entirely, but risk avoidance requires ceasing the risky activity, not upgrading the control.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Risk mitigation
The risk manager is applying risk mitigation by implementing the encryption upgrade to reduce the likelihood or impact of a data breach. This directly addresses the identified risk by deploying a stronger cryptographic control, such as moving from AES-128 to AES-256 or replacing deprecated TLS 1.0/1.1 with TLS 1.3, thereby lowering the residual risk to an acceptable level.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Risk acceptance
Why it's wrong here
Risk acceptance is a deliberate decision by an organization to take no action to reduce the likelihood or impact of a specific risk, often because the cost of mitigation outweighs the potential harm or the risk falls within the organization's established risk appetite. In this scenario, upgrading encryption represents a proactive control implementation, which is a direct action to reduce risk, thereby contradicting the principle of accepting the risk without further intervention.
- ✗
Risk avoidance
Why it's wrong here
Risk avoidance involves eliminating the activity or asset that gives rise to the risk entirely, thereby removing the possibility of the risk event occurring. If the identified risk is associated with the use of encryption, true avoidance would necessitate discontinuing the use of encryption altogether. Upgrading the encryption, however, signifies a continued engagement with the technology, merely enhancing its security rather than abandoning it.
- ✗
Risk enhancement
Why it's wrong here
"Risk enhancement" is not a recognized or standard risk treatment strategy within established cybersecurity frameworks such as ISO 27005 or NIST SP 800-30. Standard risk treatment options focus on reducing, transferring, avoiding, or accepting risks. This term might be confused with concepts like 'opportunity enhancement' in project management, but it does not apply to the management of negative risks in information security.
- ✗
Risk transfer
Why it's wrong here
Risk transfer involves shifting the financial burden or responsibility associated with a risk to a third party, typically through mechanisms like purchasing cybersecurity insurance, outsourcing a risky function, or contractual agreements. Upgrading internal encryption systems is an internal control measure designed to reduce the organization's direct exposure to the risk. It does not involve shifting the risk's financial impact or operational responsibility to an external entity.
- ✓
Risk mitigation
Why this is correct
Risk mitigation involves implementing controls or countermeasures to reduce the likelihood or impact of a risk event to an acceptable level. Upgrading to stronger encryption algorithms, increasing key lengths, or improving cryptographic protocols directly reduces the probability of a successful attack against encrypted data. This action directly lessens the organization's exposure to a data breach, aligning precisely with the definition and objective of risk mitigation.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
Learn chapter
Asset Security: Privacy and Data Retention
Key term
Risk assessment
Risk assessment is the process of identifying, analyzing, and evaluating potential threats to an organization's assets to determine the likelihood and impact of those threats, and to decide on appropriate treatment measures.
Key term
TLS
Transport Layer Security (TLS) is a cryptographic protocol that encrypts data sent over the internet to keep it private and ensure it hasn’t been tampered with.
About these practice questions
One of 747 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.